{
    "id": "CVE-2006-2407",
    "published": "2006-05-16 10:02:00",
    "last_modified": "2026-06-16 22:24:56",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": "CWE-119",
    "description": "Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.",
    "epss_score": "0.71375",
    "epss_percentile": "0.99396",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:15:02",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "freeftpd",
            "product": "freeftpd"
        },
        {
            "vendor": "freesshd",
            "product": "freesshd"
        },
        {
            "vendor": "weonlydo",
            "product": "wodsshserver"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "16461",
            "title": "freeSSHd 1.0.9 - Key Exchange Algorithm String Buffer Overflow (Metasploit)",
            "date": "2010-05-09",
            "url": "https://www.exploit-db.com/exploits/16461"
        },
        {
            "source": "exploit-db",
            "ref_id": "16462",
            "title": "freeFTPd 1.0.10 - Key Exchange Algorithm String Buffer Overflow (Metasploit)",
            "date": "2010-05-09",
            "url": "https://www.exploit-db.com/exploits/16462"
        },
        {
            "source": "exploit-db",
            "ref_id": "1787",
            "title": "freeSSHd 1.0.9 - Key Exchange Algorithm Buffer Overflow",
            "date": "2006-05-15",
            "url": "https://www.exploit-db.com/exploits/1787"
        }
    ],
    "refs_list": [
        "http://marc.info/?l=full-disclosure&m=114764338702488&w=2",
        "http://secunia.com/advisories/19845",
        "http://secunia.com/advisories/19846",
        "http://secunia.com/advisories/20136",
        "http://securityreason.com/securityalert/901",
        "http://www.kb.cert.org/vuls/id/477960",
        "http://www.osvdb.org/25463",
        "http://www.osvdb.org/25569",
        "http://www.securityfocus.com/archive/1/434007/100/0/threaded",
        "http://www.securityfocus.com/archive/1/434038/100/0/threaded",
        "http://www.securityfocus.com/archive/1/434402/100/0/threaded",
        "http://www.securityfocus.com/archive/1/434415/100/0/threaded",
        "http://www.securityfocus.com/archive/1/434415/30/4920/threaded",
        "http://www.securityfocus.com/bid/17958",
        "http://www.vupen.com/english/advisories/2006/1785",
        "http://www.vupen.com/english/advisories/2006/1786",
        "http://www.vupen.com/english/advisories/2006/1842",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/26442",
        "http://marc.info/?l=full-disclosure&m=114764338702488&w=2",
        "http://secunia.com/advisories/19845",
        "http://secunia.com/advisories/19846",
        "http://secunia.com/advisories/20136",
        "http://securityreason.com/securityalert/901",
        "http://www.kb.cert.org/vuls/id/477960",
        "http://www.osvdb.org/25463"
    ]
}